Regulating Exceptions in Healthcare Using Policy Spaces

  • Authors:
  • Claudio Agostino Ardagna;Sabrina Capitani Di Vimercati;Tyrone Grandison;Sushil Jajodia;Pierangela Samarati

  • Affiliations:
  • University of Milan, Italy;University of Milan, Italy;IBM Almaden Research Center, USA;George Mason University, USA;University of Milan, Italy

  • Venue:
  • Proceeedings of the 22nd annual IFIP WG 11.3 working conference on Data and Applications Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

One truth holds for the healthcare industry - nothing should interfere with the delivery of care. Given this fact, the access control mechanisms used in healthcare to regulate and restrict the disclosure of data are often bypassed. This "break the glass"phenomenon is an established pattern in healthcare organizations and, though quite useful and mandatory in emergency situations, it represents a serious system weakness.In this paper, we propose an access control solution aimed at a better management of exceptions that occur in healthcare. Our solution is based on the definition of different policy spaces regulating access to patient data and used to balance the rigorous nature of traditional access control systems with the prioritization of care delivery.